Earlier this month, NASAA (the North American Securities Administrators Association) released its 2025 annual report on state-registered investment advisers. And for smaller RIAs still assuming regulators are focused elsewhere, it should be a serious wake-up call.
State enforcement actions didn’t center on fraud or headline-grabbing scandals. They focused on firms missing the fundamentals—registration lapses, disclosure gaps, fee issues, and weak or outdated compliance policies.
This isn’t about malicious intent. It’s about operations that haven’t kept up with rising regulatory expectations. And most of the problems flagged are things RIAs could fix before they ever become a problem—if they knew to look.
Small Firms, Big Expectations
There are more than 16,500 state-registered investment advisers in the U.S., most of them small firms with lean internal teams and deep client relationships. These are often local businesses built on trust. But NASAA’s report makes clear: that doesn’t buy you any slack.
The fiduciary standard applies equally, whether you manage $3 million or $300 million. Regulators aren’t scaling expectations based on size—they’re scaling them based on risk. And small firms with outdated compliance frameworks? That’s risk.
What Regulators Are Actually Looking For
The most common enforcement actions in 2024 included:
- Failure to register the firm or individual representatives
- Improper or unclear fee disclosures
- Conflicts of interest not properly addressed or documented
- Missing or outdated compliance procedures
- Weak supervision or audit processes
Many of these stem from manual workflows, fragmented documentation, or compliance reviews that don’t go deep enough. In other words: not fraud—just fragile infrastructure.
What This Means for Your Firm
This report should be a checkpoint, not a panic trigger. But it should spark a meaningful review of how your compliance program operates day to day:
- Are your filings up to date, and do they reflect how your business actually works?
- Have you documented and mitigated conflicts of interest—or just mentioned them generically?
- Is your compliance manual more than a PDF on a shared drive?
- Can you point to a real, documented annual review process?
If you’re unsure on any of those, you’re not alone—but you are exposed.
Why Smartria Was Built for Exactly This
At Smartria, we work with firms that know compliance matters—but don’t have time to babysit a binder.
We give RIAs a centralized platform to: – Track disclosures and attestations – Automate annual reviews and documentation – Keep policies current—and provable – Align compliance with what regulators actually want to see
Our philosophy is simple: compliance doesn’t have to be hard—but it does have to be right. And in today’s environment, doing it manually just isn’t enough.
Bottom Line
The biggest risk facing most RIAs isn’t fraud or mismanagement. It’s the gap between how they run and what the rules require.
NASAA isn’t out to scare anyone. But they are showing their hand: Small firms are under the microscope, and enforcement is rising.
If you want your next exam to be routine—not punitive—now’s the time to close that gap.





